Netflix Phishing Attack Hides Behind a Functional CAPTCHA Page to Avoid Detection

netflix phishing scamIn an interesting twist, cybercriminals utilize a well-known technology to keep security solutions from identifying a “failed payment” email as being fraudulent.

We’ve all sat there frustrated, being asked to “click on all the boxes that contain” traffic lights, cars, bicycles, or to type in strangely-presented words – all in the name of proving we’re human. CAPTCHA is used by countless websites today as a means of keeping bots out and allowing humans to proceed on a website.

But a recent phishing attack was spotted and analyzed by security researchers at Armorblox, purporting to be from Netflix customer support with a payment issue, was found to use a CAPTCHA landing page before taking the potential victim to a spoofed Netflix logon page.


This credential scam is elegant and, dare I say, brilliant. What better tool to keep a computer from detecting if the scam’s landing page is legitimate or not than a technology designed to keep computer systems out?

In addition to keeping automated security systems from spotting the fake Netflix logon page, the use of the well-known CAPTCHA adds a layer of familiarity for potential victims, likely making them more prone to continuing through the remainder of the scam.

While organizations usually aren’t concerned about their employee’s Netflix credentials, this same method can just as easily be used to obfuscate spoofed pages designed to steal online business credentials. Educating users with Security Awareness Training on evolving tactics, such as the use of CAPTCHA, can help elevate the employee’s ability to spot a scam and avoid falling for really brilliant tactics, like the ones used in this attack.

Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Subscribe To Our Blog

Ransomware Hostage Rescue Manual

Get the latest about social engineering

Subscribe to CyberheistNews